KIProtect
Germany · kiprotect.com · 3 vendors
KIProtect develops software solutions that enable secure, legally compliant, and privacy-friendly processing of sensitive and personal data. The company offers open-source solutions for anonymization and pseudonymization, alongside products like Klaro! for consent management and Kodex for privacy and security engineering.
Resilience scores
- Digital Sovereignty: 67
- Digital Resilience: 5
- Financial Resilience: 4
Technology vendors
- Google LLC — Technology — United States
- Heinlein Support GmbH (Mailbox.org) — Technology — Germany
- Hetzner Online GmbH — Technology — Germany
Services catalogue
1 service in catalogue across 1 category; runs on 3 sub-vendors.
- Klaro
Insights
Last updated 2026-04-15 · revision 2
3 direct vendors, 57 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 2
- United States: 1
Subvendors by controlling owner country (sample)
- Switzerland: 2
- Germany: 4
- United States: 42
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
KIProtect demonstrates a strong foundation for migration readiness, primarily driven by its modern and open-source-centric technology stack. The use of Go, Python, JavaScript, GitHub, and GitHub Actions aligns well with contemporary cloud-native development practices, facilitating potential containerization and microservices adoption, even if not explicitly stated as current practices. Their strategy of offering open-source solutions (Klaro!, Kodex, dwork) inherently reduces proprietary vendor lock-in and promotes portability, which is a significant advantage for migration. Furthermore, KIProtect's core business in data protection, privacy engineering, and GDPR compliance means they possess deep internal expertise in navigating complex regulatory environments and data handling requirements. This is a critical asset for managing data residency and compliance during a cloud migration. The vendor landscape, with "Total Services: 3" from vendors in two countries (US, Germany), suggests a relatively low number of external dependencies, which generally translates to lower vendor lock-in risk and simpler contract management during a migration. However, there are notable challenges. The lack of data regarding KIProtect's financial stability (revenue, growth) makes it impossible to assess their capacity to fund a potentially costly migration initiative. While data residency requirements are "Not specified," their GDPR focus implies a high awareness, but specific requirements could still emerge as a challenge. The fact that they own their own IP address space (RIPE LIR) might indicate some existing on-premise infrastructure that would require careful planning and effort to migrate to a cloud environment. Despite these unknowns, the inherent portability of their open-source products and their strong regulatory expertise position them favorably for a successful migration.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
As a German company processing personal data (employee data, customer data, website visitors) and providing data protection services to clients, GDPR compliance is mandatory. High risk due to: (1) Maximum fines up to €20M or 4% of annual turnover, (2) Company operates in data protection sector making non-compliance particularly damaging to reputation, (3) German DPAs actively enforce GDPR, (4) Company processes personal data across multiple jurisdictions through their software products.
Evidence: https://kiprotect.com/company/imprint, https://kiprotect.com/services/data-protection-evaluations
SOC 2 (source) — Assessment Required
SOC2 may be relevant as KIProtect provides cloud-based software services (Klaro!, Kodex) that process customer data. Medium risk because: (1) SOC2 is voluntary but increasingly expected by enterprise customers, (2) Non-compliance could limit business opportunities with security-conscious clients, (3) As a data protection services provider, customers expect high security standards, (4) Enforcement is market-driven rather than regulatory.
Evidence: https://heyklaro.com, https://heykodex.com
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for KIProtect as an information security management standard. Medium risk because: (1) Certification is voluntary but demonstrates security maturity, (2) Expected by enterprise clients in data protection sector, (3) Competitive advantage in privacy/security market, (4) Non-compliance doesn't carry legal penalties but may limit business opportunities.
Evidence: https://kiprotect.com/services/data-protection-evaluations
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 4/10
KIProtect GmbH operates in a structurally attractive and growing privacy-technology market, supported by intensifying GDPR enforcement across the EU. The company has received non-dilutive public grant funding from two major German federal ministries (BMWi and BMBF), won a prestigious national founder competition including an AI special prize, and counts DATEV — one of Germany's largest IT service providers — as a reference enterprise customer. These factors provide meaningful early-stage credibility and reduce pure burn-rate risk relative to an unfunded startup. However, the company shows no evidence of external venture or private equity funding, which materially constrains its ability to invest in sales, marketing, and product development at the scale required to compete against well-resourced rivals such as OneTrust, Usercentrics, Cookiebot/Cybot, and TrustArc. The open-source monetisation model for Kodex introduces additional revenue uncertainty, and reliance on project-based grant income creates lumpy, non-recurring cash flows. The company almost certainly qualifies as a micro-entity or small GmbH under German HGB thresholds (net revenues likely ≤ €700,000, employees likely ≤ 10), which legally permits withholding revenue and P&L data from public filings. This absence of financial transparency makes independent creditworthiness assessment impossible and signals a very limited operational scale. Key-person concentration on founder Dr. Dewes and a likely very small team (estimated 1–15 employees) represent additional material risks. Overall, KIProtect presents as an early-stage, founder-led micro-company with strong intellectual credentials and regulatory tailwinds but constrained financial resources, high competitive pressure, and no verifiable quantitative financial track record. A resilience score of 4 reflects the balance between genuine qualitative strengths and the significant structural and financial vulnerabilities inherent to its scale and funding profile.
Key strengths: Non-dilutive public grant funding from BMWi and BMBF reduces early-stage burn risk, Winner of BMWi Gründerwettbewerb Digitale Innovationen including AI special prize, DATEV (major German enterprise IT provider) listed as customer/partner, TechFounders accelerator alumni (UnternehmerTUM / TU Munich), Founder Dr. Dewes holds PhD in quantum physics and has prior startup exit (QuantifiedCode acquired 2017), Structurally growing market driven by intensifying GDPR enforcement across the EU, Open-source Kodex strategy reduces customer acquisition cost and builds developer community trust, Website available in 9 languages suggesting international growth ambitions, Consortium member in BMWi-funded IIP Ecosphere research project
Risk factors: No disclosed external venture capital or private equity funding rounds, Very small team (estimated 1–15 employees) with high key-person dependency on founder Dr. Dewes, Highly competitive market with well-funded rivals (OneTrust, Usercentrics, Cookiebot/Cybot, TrustArc), Revenue concentration risk: loss of one or two key clients (e.g. DATEV) could be disproportionately impactful, Open-source monetisation challenge for Kodex limits direct software licensing revenue, Grant dependency creates lumpy, project-based, non-recurring cash flows, No public financial disclosures — impossible for counterparties to independently assess creditworthiness, Likely micro-entity scale (revenues possibly ≤ €700,000) constrains competitive investment capacity
Revenue by geography
- Germany: 0%
- International: 0%
Revenue by product/service
- Klaro! CMP SaaS: 0%
- Public Research Grants: 0%
- Kodex Enterprise Licensing / Support: 0%
- Data Protection Evaluations (Consulting): 0%
- Privacy Engineering Services (Consulting): 0%
Workforce by country
- Germany: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.